{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T11:25:03Z","timestamp":1769599503891,"version":"3.49.0"},"reference-count":60,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2013,8,1]],"date-time":"2013-08-01T00:00:00Z","timestamp":1375315200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Electron Markets"],"published-print":{"date-parts":[[2013,12]]},"DOI":"10.1007\/s12525-013-0137-3","type":"journal-article","created":{"date-parts":[[2013,7,31]],"date-time":"2013-07-31T07:49:09Z","timestamp":1375256949000},"page":"341-354","source":"Crossref","is-referenced-by-count":21,"title":["Information security governance practices in critical infrastructure organizations: A socio-technical and institutional logic perspective"],"prefix":"10.1007","volume":"23","author":[{"given":"Susan P.","family":"Williams","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Catherine A.","family":"Hardy","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Janine A.","family":"Holgate","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2013,8,1]]},"reference":[{"key":"137_CR1","unstructured":"Allen, J.H. (2005). Governing for enterprise security Technical Note CMU\/SEI-2005-TN-023. PA: The Software Engineering Institute, CERT\u00ae Carnegie Mellon University."},{"key":"137_CR2","unstructured":"Attorney General\u2019s Department (AGD) (2010). Critical infrastructure resilience strategy. Australian Government Attorney General\u2019s Department. Commonwealth of Australia: Barton, ACT"},{"key":"137_CR3","unstructured":"Caralli, R.A. (2004). Managing for enterprise security Technical Note: CMU\/SEI-2004-TN-046. The Software Engineering Institute, Carnegie Mellon University"},{"key":"137_CR4","volume-title":"Governance of enterprise security: CyLab 2012 Report","author":"Carnegie Mellon CyLab","year":"2012","unstructured":"Carnegie Mellon CyLab. (2012). Governance of enterprise security: CyLab 2012 Report. RSA: Jody R Westby."},{"key":"137_CR5","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1111\/j.1365-2575.1996.tb00015.x","volume":"6","author":"ALM Cavaye","year":"1996","unstructured":"Cavaye, A. L. M. (1996). Case study research: a multi-faceted research approach for IS. Information Systems Journal, 6, 227\u2013242.","journal-title":"Information Systems Journal"},{"issue":"6","key":"137_CR6","doi-asserted-by":"crossref","first-page":"487","DOI":"10.1016\/S0167-4048(03)00606-0","volume":"22","author":"RS Coles","year":"2003","unstructured":"Coles, R. S., & Moulton, R. (2003). Operationalizing IT risk management. Computers & Security, 22(6), 487\u2013493.","journal-title":"Computers & Security"},{"key":"137_CR7","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1080\/10580530701586136","volume":"24","author":"A Veiga Da","year":"2007","unstructured":"Da Veiga, A., & Eloff, J. H. P. (2007). An information security governance framework. Information Systems Management, 24, 361\u2013372.","journal-title":"Information Systems Management"},{"key":"137_CR8","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1111\/j.1365-2575.2006.00219.x","volume":"16","author":"G Dhillon","year":"2006","unstructured":"Dhillon, G., & Torkzadeh, G. (2006). Value-focused assessment of information system security in organizations. Information Systems Journal, 16, 293\u2013314.","journal-title":"Information Systems Journal"},{"key":"137_CR9","volume-title":"Global Security Survey The shifting security paradigm","author":"Deloitte Touche Tohmatsu (DTT)","year":"2007","unstructured":"Deloitte Touche Tohmatsu (DTT). (2007). Global Security Survey The shifting security paradigm. USA: DTT."},{"issue":"1","key":"137_CR10","doi-asserted-by":"crossref","first-page":"67","DOI":"10.2307\/41166154","volume":"45","author":"A Dutta","year":"2002","unstructured":"Dutta, A., & McCrohan, K. (2002). Management\u2019s role in information security in a cyber economy. California Management Review, 45(1), 67\u201387.","journal-title":"California Management Review"},{"issue":"4","key":"137_CR11","doi-asserted-by":"crossref","first-page":"532","DOI":"10.5465\/amr.1989.4308385","volume":"14","author":"KM Eisenhardt","year":"1989","unstructured":"Eisenhardt, K. M. (1989). Building theories from case study research. Academy of Management Review, 14(4), 532\u2013550.","journal-title":"Academy of Management Review"},{"key":"137_CR12","doi-asserted-by":"crossref","first-page":"389","DOI":"10.4135\/9781849200387.n16","volume-title":"The SAGE handbook of organizational institutionalism","author":"PC Fiss","year":"2008","unstructured":"Fiss, P. C. (2008). Institutions and corporate governance. In R. Greenwood, C. Oliver, K. Sahlin, & R. Suddaby (Eds.), The SAGE handbook of organizational institutionalism (pp. 389\u2013410). London: SAGE Publications Ltd."},{"issue":"2","key":"137_CR13","doi-asserted-by":"crossref","first-page":"19","DOI":"10.4102\/sajbm.v34i2.679","volume":"34","author":"LCH Fourie","year":"2003","unstructured":"Fourie, L. C. H. (2003). The management of information security - A South African case study. South African Journal of Business Management, 34(2), 19\u201329.","journal-title":"South African Journal of Business Management"},{"issue":"3","key":"137_CR14","doi-asserted-by":"crossref","first-page":"106","DOI":"10.1108\/09685220310480381","volume":"11","author":"H Fulford","year":"2003","unstructured":"Fulford, H., & Doherty, N. F. (2003). The application of information security policies in large UK-based organizations: an exploratory investigation. Information Management & Computer Security, 11(3), 106\u2013114.","journal-title":"Information Management & Computer Security"},{"key":"137_CR15","volume-title":"Survey analysis: Information security governance, 2012","author":"Gartner","year":"2012","unstructured":"Gartner. (2012). Survey analysis: Information security governance, 2012. Gartner: Tom Scholtz."},{"issue":"1","key":"137_CR16","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.cose.2004.11.002","volume":"24","author":"M Gerber","year":"2005","unstructured":"Gerber, M., & von Solms, R. (2005). Management of risk in the information age. Computers & Security, 24(1), 16\u201330.","journal-title":"Computers & Security"},{"key":"137_CR17","doi-asserted-by":"crossref","unstructured":"Granovetter, M. (1985). Economic action and social structure: the problem of embeddedness. American Journal of Sociology, 91, 481\u2013510.","DOI":"10.1086\/228311"},{"key":"137_CR18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.4135\/9781849200387.n1","volume-title":"The SAGE handbook of organizational institutionalism","author":"R Greenwood","year":"2008","unstructured":"Greenwood, R., Oliver, C., Sahlin, K., & Suddaby, R. (2008). Introduction. In R. Greenwood, C. Oliver, K. Sahlin, & R. Suddaby (Eds.), The SAGE handbook of organizational institutionalism (pp. 1\u201346). London: SAGE Publications Ltd."},{"issue":"2","key":"137_CR19","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1016\/S0923-4748(02)00018-8","volume":"19","author":"T Griffith","year":"2002","unstructured":"Griffith, T., & Dougherty, D. J. (2002). Beyond socio-technical systems: introduction to the special issue. Journal of Engineering and Technology Management, 19(2), 205\u2013216.","journal-title":"Journal of Engineering and Technology Management"},{"key":"137_CR20","unstructured":"Holgate, J.A. (2007). Governance arrangements for enterprise information protection: an Australian critical infrastructure perspective. (Doctoral Thesis, University of Sydney)"},{"key":"137_CR21","unstructured":"Holgate J.A., Williams S.P. and Hardy C.A. (2012). \u2018Information Security Governance: Investigating Diversity in Critical Infrastructure Organizations (Awarded \u2018Bled Theme Outstanding Paper\u2019), Proceedings of the 25th Bled eConference 2012, Bled, Slovenia, 20th June 2012."},{"key":"137_CR22","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1016\/j.jsis.2007.05.004","volume":"16","author":"Q Hu","year":"2007","unstructured":"Hu, Q., Hart, P., & Cooke, D. (2007). The role of external and internal influences on information systems security\u2014a neo-institutional perspective. The Journal of Strategic Information Systems, 16, 153\u2013172.","journal-title":"The Journal of Strategic Information Systems"},{"key":"137_CR23","unstructured":"Information Systems and Control Association\u00ae. (2010). The business model for information security ISACA\u00ae Rolling Meadows, IL USA: Rolf M. von Roessing"},{"key":"137_CR24","volume-title":"COBIT\u00ae 5 for Information Security, ISACA\u00ae","author":"Information Systems and Control Association\u00ae","year":"2012","unstructured":"Information Systems and Control Association\u00ae. (2012). COBIT\u00ae 5 for Information Security, ISACA\u00ae. IL: Rolling Meadows."},{"key":"137_CR25","unstructured":"Information Technology Governance Institute\u2122. (2001). Information security governance: guidance for boards of directors and executive management. Information Systems Audit and Control Foundation\u2122 (ISACF). Rolling Meadows, IL, USA: ITGI\u2122."},{"key":"137_CR26","volume-title":"Information security governance: Guidance for information security managers ITGI\u2122","author":"Information Technology Governance Institute\u2122","year":"2008","unstructured":"Information Technology Governance Institute\u2122. (2008). Information security governance: Guidance for information security managers ITGI\u2122. Rolling Meadows: W. Krag Brotby."},{"key":"137_CR27","unstructured":"Information Technology Governance Institute\u2122. (2011). Global Status Report on the Governance of Enterprise (GEIT)-2011."},{"key":"137_CR28","volume-title":"ISO\/IEC 27014:2013 Information technology\u2014Security techniques\u2014Governance of information security","author":"International Organization for Standardization (ISO)","year":"2013","unstructured":"International Organization for Standardization (ISO). (2013). ISO\/IEC 27014:2013 Information technology\u2014Security techniques\u2014Governance of information security. Rolling Meadows: ITGI\u2122."},{"key":"137_CR29","volume-title":"Board briefing on IT governance","author":"IT Governance Institute (ITGI)","year":"2006","unstructured":"IT Governance Institute (ITGI). (2006). Board briefing on IT governance (2nd ed.). IL: ITGI Rolling Meadows.","edition":"2"},{"issue":"1","key":"137_CR30","doi-asserted-by":"crossref","first-page":"126","DOI":"10.1145\/1435417.1435446","volume":"52","author":"A Johnston","year":"2009","unstructured":"Johnston, A., & Hale, R. (2009). Improved security through information security governance. Communications of the ACM, 52(1), 126\u2013129.","journal-title":"Communications of the ACM"},{"issue":"5","key":"137_CR31","doi-asserted-by":"crossref","first-page":"402","DOI":"10.1108\/09685220610707421","volume":"14","author":"M Karyda","year":"2006","unstructured":"Karyda, M., Mitrou, E., & Quirchmayr, G. (2006). A framework for outsourcing IS\/IT security services. Information Management & Computer Security, 14(5), 402\u2013415.","journal-title":"Information Management & Computer Security"},{"issue":"3","key":"137_CR32","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1108\/09685220010339192","volume":"8","author":"SA Kokolakis","year":"2000","unstructured":"Kokolakis, S. A., Demopoulos, A. J., & Kiountouzis, E. A. (2000). The use of business process modelling in information systems security analysis and design. Information Management & Computer Security, 8(3), 107\u2013116.","journal-title":"Information Management & Computer Security"},{"key":"137_CR33","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1016\/S0923-4748(01)00035-2","volume":"18","author":"A Majchrzak","year":"2001","unstructured":"Majchrzak, A., & Borys, B. (2001). Generating testable socio-technical systems theory. Journal of Engineering and Technology Management, 18, 219\u2013240.","journal-title":"Journal of Engineering and Technology Management"},{"key":"137_CR34","unstructured":"McFadzean, E., Ezingeard, J.-N., & Birchall, D. (2004). Anchoring information security governance research: sociological groundings and future directions. Proceedings of the Third Security Conference, Las Vegas."},{"issue":"5","key":"137_CR35","doi-asserted-by":"crossref","first-page":"622","DOI":"10.1108\/14684520710832333","volume":"31","author":"E McFadzean","year":"2007","unstructured":"McFadzean, E., Ezingeard, J.-N., & Birchall, D. (2007). Perception of risk and the strategic impact of existing IT on information security strategy at board level. Online Information Review, 31(5), 622\u2013650.","journal-title":"Online Information Review"},{"key":"137_CR36","volume-title":"Qualitative data analysis: an expanded sourcebook","author":"MB Miles","year":"1994","unstructured":"Miles, M. B., & Huberman, A. M. (1994). Qualitative data analysis: an expanded sourcebook (2nd ed.). Thousand Oaks: SAGE Publications, Inc.","edition":"2"},{"issue":"7","key":"137_CR37","doi-asserted-by":"crossref","first-page":"580","DOI":"10.1016\/S0167-4048(03)00705-3","volume":"22","author":"R Moulton","year":"2003","unstructured":"Moulton, R., & Coles, R. S. (2003). Applying information security governance. Computers & Security, 22(7), 580\u2013584.","journal-title":"Computers & Security"},{"issue":"2","key":"137_CR38","doi-asserted-by":"crossref","first-page":"145","DOI":"10.2307\/3250927","volume":"25","author":"W Orlikowski","year":"2001","unstructured":"Orlikowski, W., & Barley, S. (2001). Technology and institutions: what can research on information technology and research on organizations learn from each other? MIS Quarterly, 25(2), 145\u2013165.","journal-title":"MIS Quarterly"},{"key":"137_CR39","doi-asserted-by":"crossref","first-page":"461","DOI":"10.1007\/s11186-008-9069-x","volume":"37","author":"T Pinch","year":"2008","unstructured":"Pinch, T. (2008). Technology and institutions: living in a material world. Theory and Society, 37, 461\u2013483.","journal-title":"Theory and Society"},{"issue":"8","key":"137_CR40","doi-asserted-by":"crossref","first-page":"638","DOI":"10.1016\/j.cose.2004.10.006","volume":"23","author":"S Posthumus","year":"2004","unstructured":"Posthumus, S., & von Solms, R. (2004). A framework for the governance of information security. Computers & Security, 23(8), 638\u2013646.","journal-title":"Computers & Security"},{"key":"137_CR41","volume-title":"The coding manual for qualitative researchers","author":"J Salda\u00f1a","year":"2009","unstructured":"Salda\u00f1a, J. (2009). The coding manual for qualitative researchers. London: Sage."},{"issue":"7","key":"137_CR42","doi-asserted-by":"crossref","first-page":"620","DOI":"10.1016\/S0167-4048(01)00712-X","volume":"20","author":"EE Schultz","year":"2001","unstructured":"Schultz, E. E., Proctor, R. W., Lien, M.-C., & Salvendy, G. (2001). Usability and security: an appraisal of usability issues in information security methods. Computers & Security, 20(7), 620\u2013634.","journal-title":"Computers & Security"},{"key":"137_CR43","doi-asserted-by":"crossref","first-page":"427","DOI":"10.1007\/s11186-008-9067-z","volume":"37","author":"WR Scott","year":"2008","unstructured":"Scott, W. R. (2008). Approaching adulthood: the maturing of institutional theory. Theory and Society, 37, 427\u2013442.","journal-title":"Theory and Society"},{"key":"137_CR44","volume-title":"Interviewing as qualitative research: a guide for researchers in education and the social sciences","author":"I Seidman","year":"1998","unstructured":"Seidman, I. (1998). Interviewing as qualitative research: a guide for researchers in education and the social sciences (2nd ed.). New York: Teachers College Press.","edition":"2"},{"key":"137_CR45","unstructured":"Siponen, M.T., & Willison, R. (2007). A critical assessment of IS Security research between 1990\u20132004. In H. \u00d6sterle, J. Schelp & R. Winter (Eds.), Proceedings of the 15th European Conference on Information Systems (pp.1551\u20131559), St. Gallen, Switzerland."},{"key":"137_CR46","first-page":"5","volume-title":"Information security policies, processes and practices","author":"DW Straub","year":"2008","unstructured":"Straub, D. W., Goodman, S., & Baskerville, R. L. (2008). Framing the information security process in modern society. In D. W. Straub, S. Goodman, & R. L. Baskerville (Eds.), Information security policies, processes and practices (pp. 5\u201312). Armonk: ME Sharpe, Inc."},{"issue":"4","key":"137_CR47","doi-asserted-by":"crossref","first-page":"441","DOI":"10.2307\/249551","volume":"22","author":"DW Straub","year":"1998","unstructured":"Straub, D. W., & Welke, R. J. (1998). Coping with systems risk: security planning models for management decision making. MIS Quarterly, 22(4), 441\u2013469.","journal-title":"MIS Quarterly"},{"key":"137_CR48","unstructured":"The Institute of Internal Auditors. (2010). Global Technology Audit Guide (GTAG\u00ae) 15 Information Security Governance The Institute of Internal Auditors (IIA), USA: Paul Love, James Reinhard, A. Schwab & George Spafford."},{"issue":"1","key":"137_CR49","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1016\/j.cose.2004.10.005","volume":"24","author":"K-L Thomson","year":"2005","unstructured":"Thomson, K.-L., & Von Solms, R. (2005). Information security obedience: a definition. Computers & Security, 24(1), 69\u201375.","journal-title":"Computers & Security"},{"key":"137_CR50","doi-asserted-by":"crossref","unstructured":"Thornton, P., & Ocasio, W. (1999). Institutional logics and the historical contingency of power in organizations: executive succession in the higher education publishing industry, 1958\u20131990. American Journal of Sociology, 105(3), 801\u2013843.","DOI":"10.1086\/210361"},{"key":"137_CR51","doi-asserted-by":"crossref","first-page":"99","DOI":"10.4135\/9781849200387.n4","volume-title":"The SAGE Handbook of Organizational Institutionalism","author":"PH Thornton","year":"2008","unstructured":"Thornton, P. H., & Ocasio, W. (2008). Institutional logic. In R. Greenwood, C. Oliver, K. Sahlin, & R. Suddaby (Eds.), The SAGE Handbook of Organizational Institutionalism (pp. 99\u2013129). London: Sage."},{"key":"137_CR52","doi-asserted-by":"crossref","DOI":"10.1093\/acprof:oso\/9780199601936.001.0001","volume-title":"The institutional logics perspective, a new approach to culture, structure and process","author":"PH Thornton","year":"2012","unstructured":"Thornton, P. H., Ocasio, W., & Lounsbury, M. (2012). The institutional logics perspective, a new approach to culture, structure and process. Oxford: Oxford University Press."},{"issue":"1","key":"137_CR53","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1108\/09685220410518856","volume":"12","author":"V Tsoumas","year":"2004","unstructured":"Tsoumas, V., & Tryfonas, T. (2004). From risk analysis to effective security management: towards an automated approach. Information Management & Computer Security, 12(1), 91\u2013101.","journal-title":"Information Management & Computer Security"},{"issue":"3","key":"137_CR54","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1108\/09685220210431872","volume":"10","author":"C Vermeulen","year":"2002","unstructured":"Vermeulen, C., & von Solms, R. (2002). The information security management toolbox\u2014taking the pain out of security management. Information Management & Computer Security, 10(3), 119\u2013125.","journal-title":"Information Management & Computer Security"},{"issue":"3","key":"137_CR55","doi-asserted-by":"crossref","first-page":"215","DOI":"10.1016\/S0167-4048(01)00305-4","volume":"20","author":"B Solms Von","year":"2001","unstructured":"Von Solms, B. (2001). Corporate governance and information Security. Computers & Security, 20(3), 215\u2013218.","journal-title":"Computers & Security"},{"key":"137_CR56","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1016\/j.cose.2005.02.002","volume":"24","author":"B Solms Von","year":"2005","unstructured":"Von Solms, B. (2005). Information security governance: COBIT or ISO 17799 or both? Computers & Security, 24, 99\u2013104.","journal-title":"Computers & Security"},{"key":"137_CR57","doi-asserted-by":"crossref","first-page":"271","DOI":"10.1016\/j.cose.2005.04.004","volume":"24","author":"B Solms Von","year":"2005","unstructured":"Von Solms, B., & Von Solms, R. (2005). From information security to\u2026business security. Computers & Security, 24, 271\u2013273.","journal-title":"Computers & Security"},{"key":"137_CR58","volume-title":"Interpreting information systems in organizations","author":"G Walsham","year":"1993","unstructured":"Walsham, G. (1993). Interpreting information systems in organizations. Chichester: Wiley."},{"key":"137_CR59","first-page":"46","volume-title":"Information security, policy, processes, and practices","author":"M Warkentin","year":"2008","unstructured":"Warkentin, M., & Johnston, A. C. (2008). In D. W. Straub, S. Goodwin, & R. L. Baskerville (Eds.), Information security, policy, processes, and practices (pp. 46\u201368). USA: ME. Sharpe, Inc."},{"issue":"1","key":"137_CR60","doi-asserted-by":"crossref","first-page":"67","DOI":"10.2307\/25148829","volume":"32","author":"Y Xue","year":"2008","unstructured":"Xue, Y., Liang, H., & Boulton, W. R. (2008). Information technology governance in information technology investment decision processes: the impact of investment characteristics, external environment and internal context. MIS Quarterly, 32(1), 67\u201396.","journal-title":"MIS Quarterly"}],"container-title":["Electronic Markets"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12525-013-0137-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s12525-013-0137-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12525-013-0137-3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,8,1]],"date-time":"2020-08-01T04:29:34Z","timestamp":1596256174000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s12525-013-0137-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,8,1]]},"references-count":60,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2013,12]]}},"alternative-id":["137"],"URL":"https:\/\/doi.org\/10.1007\/s12525-013-0137-3","relation":{},"ISSN":["1019-6781","1422-8890"],"issn-type":[{"value":"1019-6781","type":"print"},{"value":"1422-8890","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,8,1]]}}}